Tag

#Linux malware

6 stories taggedLinux malware.

Aerial view, 16:9 framing, photoreal editorial style, a dense suburban neighbourhood at dusk with hundreds of softly glowing house windows, each window subtly e
Threat Intelligence

Zombie Cards, Cut Cables, and a Botnet: The Week's Cybercrime Stories You May Have Missed

A DDoS attack on encrypted messaging app Threema, a new Linux botnet called Evooo1Bot, and T-Mobile physically severing a cable to stop an intrusion all made news this week. Here is what happened.

3 min read
Full-frame edge-to-edge photoreal overhead shot of a tangle of consumer networking gear — a stacked home router, an IP camera, and a small Android set-top box —
Threat Intelligence

New Evooo1Bot malware is quietly turning home routers into criminal traffic relays

Researchers say the Mirai-based botnet has been hijacking gateway devices since July to sell as proxies, steal credentials, and launch attacks.

4 min read
Full-frame edge-to-edge photoreal overhead shot of a darkened developer workstation, glowing monitor showing abstract green and amber code reflections, a faint
Threat Intelligence

Arch Linux freezes package adoptions after wave of malware sneaks into user repository

A stealer that harvests browser logins, crypto wallets and SSH keys has spread through more than 200 community-maintained Arch packages, forcing the project to hit pause.

4 min read
Threat Intelligence

AUR Supply-Chain Hit: 400+ Arch Packages Backdoored With Rust Stealer, Optional eBPF Rootkit

Build scripts in hijacked Arch User Repository packages dropped a credential harvester — and an eBPF rootkit when root was available.

2 min read
Threat Intelligence

VerdantBamboo Ports BRICKSTORM to BSD, Goes Hunting for Linux Appliances

A China-nexus crew is rewriting its toolkit to live on the boxes most EDR vendors forgot about.

2 min read
Threat Intelligence

Showboat: A Modular Linux Backdoor Quietly Camped in a Middle East Telco Since 2022

Lumen's Black Lotus Labs ties the SOCKS5-capable implant to a years-long intrusion at a regional carrier, with an in-memory loader and ELF payloads that sidestep most host telemetry.

2 min read
© 2026 Threat Vectr